Privacy, security, data and support
SpaceSite reads the Confluence pages you choose to publish and turns them into a static site. This page explains exactly what data that involves, where it lives, how long we keep it, and how to reach us. For the full legal text, see the documents linked below.
What SpaceSite processes
| Category | Data | Where it lives |
|---|---|---|
| Confluence admin | Atlassian cloud id, space key, and the account id and display name of the admin who enables a space | Forge storage inside your Atlassian tenant; cloud id and space key also on Cloudflare D1 as site identifiers |
| Published content | The HTML export, attachments, images, titles, hierarchy, labels and version numbers of the pages in the space you publish | Cloudflare R2 (EU jurisdiction) and D1 (EU location hint) |
| Author data | Names, account ids and avatars found in the export | Removed before publishing by default; kept only if you opt in to show authors |
| Site visitors | IP address, user agent and requested URL, processed in memory to serve the page | Cloudflare Workers; technical logs for 7 days, without page content |
What SpaceSite does not process
- Private or restricted pages. Pages with view restrictions are never published; they do not even leave your tenant.
- No viewer tracking. Published sites set no tracking cookie, run no analytics and build no visitor profiles.
- No side content. No comments, page history, granular permissions, Jira data, or content of spaces you did not enable.
- No Atlassian tokens. OAuth and API tokens stay inside Forge and are never sent to or stored on Cloudflare.
Read-only access
The Forge app requests read-only Confluence scopes only, plus app storage. It requests no write scope: read:confluence-content.summary, read:confluence-space.summary, read:page:confluence, read:attachment:confluence, readonly:content.attachment:confluence, read:content.restriction:confluence, read:label:confluence, read:space:confluence, storage:app. External egress is declared to a single host, api.spacesite.dev.
Where your data lives, and for how long
| Data | Location | Retention |
|---|---|---|
| Site content and attachments | Cloudflare R2, EU jurisdiction | Until you delete the site or uninstall the app |
| Site metadata, sync state, aggregated counters | Cloudflare D1, EU location hint | Same |
| Compute | Cloudflare Workers, global network (a request runs closest to the visitor) | In memory only |
| Technical logs (no page content, no tokens) | Cloudflare Workers | 7 days |
When you delete a site or uninstall the app, everything (R2 objects and D1 rows) is purged within 24 hours, and in practice immediately.
Data residency is not declarable. Because content is stored on Cloudflare, outside Atlassian, SpaceSite is not eligible for Atlassian's "Runs on Atlassian" or data residency (PINNED) status, and we state this in the Marketplace listing. The EU jurisdiction (R2) and EU location hint (D1) are hints, not a contractual residency guarantee.
Legal documents
FAQ
What are the limits?
A space can hold up to 2,000 pages; a larger space stops with a clear message. Attachments above the size limit are skipped and listed in the warnings report. See Rendering and warnings.
Are dynamic macros rendered live?
No. Dynamic macros (Jira issues, page properties reports, roadmaps, calendars and similar) are not re-run on your site. They appear as a placeholder with a link back to Confluence, or as a passive snapshot of what the export contained. Every affected page is listed in the warnings report; details in Rendering and warnings.
Can I use my own domain, or password-protect the site?
Coming soon. The current version serves your site on {slug}.spacesite.dev. Custom domains (via Cloudflare for SaaS) and password protection are planned and not part of this release yet.
Do you track my site's visitors?
No. Published sites run no visitor analytics and set no tracking cookie.
Support
Support is asynchronous only, by email, in English or Italian, on business days. There is no phone line, live chat or scheduled demo, and no uptime SLA (see the EULA). Write to info@spacesite.dev. Once the open-source Space Exporter CLI is published, its GitHub issues will serve as a second channel for export bugs.
To solve most questions on your own, start with the docs overview, Getting started, Publishing and sync, Rendering and warnings and Pricing and licensing.